Requesting check of scan logs.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Virginian17, Dec 5, 2009.

  1. Virginian17

    Virginian17 Private E-2

    A long time ago, we noticed a program with Chinese characters on the computer. We disabled it and forgot about it.

    We have since installed WinPatrol. It repeatedly pops up a window saying that a new startup program has been added, but details are entirely blank. There is no icon, no title, and no manufacturer. When we try to deny the program, we get a scary message saying it is in a key location for Windows and should not be nuked unless we are sure it's safe to do so. If we deny it anyway, the alert keeps coming back.

    We haven't noticed any other strange behavior or problems on the computer, but I thought a cleaning was in order given these issues.

    We are running Windows Vista Home Premium on an Acer Aspire E380desktop.

    We ran your procedure, and logs are attached. Thank you very much for any help you can give!
     

    Attached Files:

  2. Virginian17

    Virginian17 Private E-2

    Here is the additional log. Thanks for being here....It's much, much appreciated!
     

    Attached Files:

  3. Virginian17

    Virginian17 Private E-2

    Oh, one more observation:

    When we boot up now, there is a window indicated on the taskbar for eRecoveryAgent that does not pop up into an actual window when you click on it. If you right-click it, the options are:

    Move
    Close
    (Chinese characters) ERAgent(A)...


    I do not know what this means.

    Thanks again for your help.
     
  4. Virginian17

    Virginian17 Private E-2

    I just got barraged with a bunch of startup program alerts from WinPatrol, and one alert for a new Windows service. They included the following:

    1. SysMonitor.exe
    2. (Acer Assist) launcher.exe
    3. ??????????????e (No other information given)
    4. eAPLauncher.exe
    5. (blank program - No other information given, same warning)
    6. New Windows Service: appmgmts (in system 32)

    If I deny any of them, the alerts keep coming back.



    Also, I just noticed a new file on the desktop, desktop.ini. It reads as follows:

    [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
    IconResource=%SystemRoot%\system32\imageres.dll,-183
    [LocalizedFileNames]
    Windows Mail.lnk=@%ProgramFiles%\Windows Mail\WinMail.exe,-225
    Internet Explorer.lnk=@%windir%\System32\ie4uinit.exe,-731


    Thank you again for your help.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First lets deal with a few things that we can remove. Then allow all the things that winpatrol is asking for approval for. The desktop.ini file was unhidden when you ran MGTools...it is fine.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Windows\Temp\jetb337.tmp
    C:\Users\atlantic\AppData\Local\temp\Rar$EX00.066

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
    Last edited: Dec 8, 2009
  6. Virginian17

    Virginian17 Private E-2

    Sorry for the delay in responding, and thank you for still being here. Norton Internet Security expired since I wrote to you. I put Panda Internet Security on the computer, instead. Panda did not identify any malware.

    Since adding Panda Internet Security to the computer, I have not noticed any WinPatrol alerts; however, the mysterious "???????????" file is still listed in startup. Also, I have been getting alerts about network intruders, which is new (but I don't know if Norton even had this capability).

    The registry addition you gave me was successful. However, I cannot find either of the files you instructed me to delete.

    The only files in C:\Windows\Temp are cteng*.dat files (a whole bunch), MP*.log files (2), and PSSysChk.log.

    When I go to C:\Users\atlantic\AppData\Local\temp, there are folders for eDataSecurity, Low, and WPDNSE. There are files for ~DF*.tmp (a whole bunch), atlantic.bmp, and jusched.log. I cannot find anything like Rar$EX00.066.

    If I were on XP, I would do a search for the files to see if they could be anywhere else, but the Vista search engine perplexes me. I tried to search from the box on top of the C: drive window and it didn't find anything, but I am not positive I did the search correctly.


    I ran the C:\MGtools\GetLogs.bat file. The log is attached.

    Thank you again for helping me figure this out. I am so grateful for your help.
     
  7. Virginian17

    Virginian17 Private E-2

    Sorry. Here is the MGTools log.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There are only two things I would like you to delete. Please use windows explorer to find and delete:
    C:\Windows\Tasks\at1.job
    C:\Windows\Tasks\WebReg 20071029141641.job

    Now, If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  9. Virginian17

    Virginian17 Private E-2

    Thank you very much for identifying those files. I did delete them. They did not appear in the recycle bin on the desktop, but I found them in C:\$RECYCLE.BIN\Recycle Bin. There is also a file in the $RECYCLE.BIN folder called S-1-5-21-1184643003-4113689745-3837433256-1000, to which access is denied (the icon is faded out). I don't understand why I have a recycle bin on the desktop and then this file in C.

    I have a couple of other questions, if you don't mind. In googling the at1.job file, what I have found seems to suggest that the file is created by other malware or network shares and reflects a task associated with malware, rather than the malware itself (if that makes sense). I am wondering why deleting the job file is enough to make sure the problem is entirely gone.

    Do you have an idea of how the job files got there, and how I can be sure I am not still vulnerable to a problem? I don't understand shares at all. How can I ensure that my shares are all valid?

    Also, I still have the mystery ?????????? file in startup. What was your thought about this file? Do you have any idea what it is?

    I'm sorry if these are stupid questions, and I hope you don't mind my asking them. I very much appreciate your help and expertise.
     
  10. Virginian17

    Virginian17 Private E-2

    at1.job is back again today, after having been deleted yesterday.

    i also found it on our other computer, also in the Tasks folder. please help me understand what's happening here.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am sorry for the delay. You should open msconfig .....go to start/ run / and type:
    msconfig. Once that opens, go to the startup tab and uncheck that "mystery" file.

    Then reboot and run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds